A vulnerability has been identified in various Cisco routers, which could be exploited by remote attackers to take complete control of an affected device. This flaw is due to an error in the default IOS configuration shipped with the Cisco Router Web Setup (CRWS) application that does not include an "enable password" or an "enable secret" command, which could be exploited by remote unauthenticated attackers to access the Cisco IOS HTTP server interface and execute arbitrary commands with level 15 privileges (the highest privilege level on Cisco IOS devices).
Credits
Vulnerability reported by the vendor
ChangeLog
2006-07-12 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.